Showing posts with label vmware. Show all posts
Showing posts with label vmware. Show all posts

Thursday, April 30, 2009

Laptop PWN3D!


It took three tries and as usual OpenVPN stability was an issue, but I finally stole my own laptop without ever touching it.

It took almost thirteen hours, but that's within the limits of an unattended laptop in a "secure" location. Not everyone takes their laptop home, and if you work in an environment like I do, nobody likes to log off or reboot because it takes at the very least twenty minutes for your system to get back to normal (our specific problem is Outlook - it really has a hard time waking up in the morning).

Granted, the hard disk only had 20G of data on it. A bigger drive would have taken more time, bleeding into working hours and increasing the likelihood of an OpenVPN interruption, but as a Proof of Concept (PoC) the results are valid.

It would have taken four hours had the VMware vConverter taken full advantage of my cable connection. It never went over 585kBps for the duration of the transfer.

The first two attempts never went over 400. On those runs I was using vConverter 3.x. I upgraded to 4.x before the final run. I have a feeling, which I can't prove, that the free versions of the VMware Infrastructure tools might be crippleware. There is no reason for it not to have taken full advantage of my pipe. I have gotten the full bandwidth in other file transfer exercises between home and work and the CPU utilization on the source and destination systems was minimal-to-nothing.

As an added bonus, it turns out that nothing on the network even noticed that gigabytes of data were being sent out to the Internet for three full days! No alarms went off. No red flags went up. It didn't even show up in the reports generated every day by the Microsoft ISA (Internet Security & Acceleration) servers that "control and monitor" access to the Internet.

Unbelievable! Especially considering it was me who set those reports up (and I wasn't even trying to hide anything).

The skeptics (I among them) will say, "Sure, you had admin access to the machine, what is so special about this 'hack'?"

That, my friends, is the whole point of this PoC. The environment I work in has 50+ "DesktopSupport" personnel that have admin access to every PC in our multi-campus WAN. Some of these people are complete, utter bozos who have been known to do idiotic things like Google for "flash upgrade" and then complain because the file they downloaded from a Ukrainian Web site gets pounced on by the anti-virus.

They are not too bright. Maybe that was an upper management decision. I could see the logic in that, but in my opinion stupid people are dangerous.

The problem is the smart ones, and the smart ones who act dumb (the dumb ones who act smart usually blow their own cover anyway).

This group of support personnel should be split up to support the different campuses, but with sick days, vacations, and scheduling conflicts it's just easier to give them access to everything.

Luckily, almost no one trusts them. But there is the "out of sight, out of mind" problem.

That aside, the Really Scary Issue - in my own mind - is my Big Shot Boss, the Chief Security Officer, cannot seem to grasp the power they have. Sure, the guy's at 35,000 feet and everyone looks like ants, but he's been out of the trenches for so long he doesn't realize what people can do with the access they have been handed on a silver platter.

He doesn't know that, by utilizing the tools built-in to Windows, these jokers can slurp up any file on any hard drive on any desktop across the Enterprise, deleting the security logs as they exit. If those logs were turned on, which they're not.

To him, and the rest of his ilk, the security problems we face are all about servers. Nobody cares that the desktop is an accident waiting to happen. When the desktop is pwn3d, the servers, the network, and the data will surely follow.

It's never the other way around.

Tuesday, April 28, 2009

I'm Stealing A Laptop Today!


Don't get excited. I haven't gone over to the Dark Side.

Yet.

Besides, it's my own laptop. That is, it's the laptop my employer has issued to me. And I'm not taking it home in my lunch box. This time.

I'm stealing it virtually!

You see, nobody steals laptops for the hardware anymore. It's all about the data. With the right access level, laptops, or any computer, can be stolen without ever busting a lock or leaving a fingerprint.

All with free tools easily available over the Internet. I'm not talking about "hacking tools" - you have to be brave to use that crap these days because you never know what might be hiding in them - I'm talking about legitimate software distributed by legitimate companies. In this case, VMware.

VMware distributes a nice little tool called the VMware vCenter Converter which allows you, among other things, to turn a real nuts and bolts box into a virtual machine.

Which is exactly what I'm doing now. As I type this, the bits and bytes of the hard disk in my laptop are flying over the Internet to a VMware server in my family room. When it's all over I will have an exact copy of my laptop, minus the hardware of course.

This is really No Big Deal. Anyone with the right amount of access can do this surreptitiously in your IT environment, cut the image to a USB thumb drive and take it home to hack at their leisure. Or sell to the highest bidder.

The trick is in doing it over the Internet. If I had a 32G USB drive I'd probably do it that way, but I don't. What I do have is a cable modem and three covert channels back to the office.

Plus an aging Linux box that I talked a former Boss into letting me install on the corporate network over eight years ago. If I had my way, Linux would only be allowed under the strictest security policy possible - it's just too damned powerful for mere mortals.

The biggest problem to overcome is establishing a common network share for the corporate and VMware boxes. That is accomplished with OpenVPN, the BEST damned Open Source SSL VPN on the planet.

That is covert channel #1. Channels 2 and 3 are port-forwarding SSH tunnels that connect back to HinkyNet over the corporate proxy. One of the SSH channels is established with a Cygwin service running on my corp workstation. The other is a bash script on a Debian VM that runs on the VMware GSX server on my workstation. All three will reconnect if the workstation is bounced and there is enough redundancy so that if any two of them go down the third can be used to bring the other two back up.

In practice, OpenVPN is the hardest to keep running, but that is due to the security limitations in our environment (many of which are of my own doing).

And because of that issue, I'm on my second attempt at this Proof of Concept exercise. I started yesterday and got 15 gigs downloaded before the OpenVPN connection crashed at 5AM this morning. I can also do this just as easily over SSH tunnels, but that would require using the VMware 2.0 server on my MythTV box, which currently has too much disk space dedicated to unwatched recordings of "Terminator" and "Life on Mars"!

The first time through is always a learning experience.

But the point remains: given enough time and enough access and the right tools, an insider can walk away with your company's entire IT infrastructure. I'm already looking into what can be done about this with the tools our company already has (like everyone else in this economy we're not spending cash we don't have). VMware and virtualization in general is so hot, no one is looking into the security implications these tools bring with them.

Or at least they're not publishing.

Saturday, June 30, 2007

VNC 4

Years ago, before I was a High Paid IT Security Dude and UT99 Server Jockey, I was a High Paid Computer Consultant Geek. This was way back in pre-millennial times (1995-2000). For the most part, it was a decent job. I worked for a "Value Added Reseller". A gig here, a gig there. Replace parts, install software, get a new network up and running, that kind of thing. None of that long-term "body shop" bullshit where they sit your ass down in a cubicle and you're expected to mine for opportunities to get more billing bodies on-site (although, sadly, it eventually degraded down to that level).

I fixed broken computer shit and told people what to do and how to do it.

I also told them what not to do.

One of the things I evangelized against to every customer I ever had was the pure evil that was PCAnywhere. They never listened.

Ah, the horror stories I could tell you.

Like the Hospital IT staffer who decided to install PCAnywhere on a "mission-critical" Windows NT4 billing system at 4:30PM on a Friday afternoon. I didn't get out of there until 3PM the next afternoon. Good times, good times.

Everywhere you went, PCAnywhere was blue screening Windows servers. It didn't matter what version or which service pack. It simply blew up servers (in the NT 3.51 days, if you uninstalled a certain version of PCAnywhere it would delete every single file on the partition it was installed on - fun stuff!).

And everywhere you went the resident Windows honcho (the guy who convinced management to spend $50K on a PCAnywhere site license) always said "We've never had any problems with it."

All that disappeared after Windows 2000 and RDP (Remote Desktop Protocol) entered the stage. Some, like the dot-com I worked for before the bust, clung to PCAnywhere because it was somehow simply better than RDP (and they had already dropped the $50K on the site license). And they paid the price with server crashes, day after day.

While all that was going on, an Open Source project called VNC was maturing. In the Blue Screen of Death (BSOD) department, it had a similar track record. Sometimes, depending on your video driver, it was just plain fugly. But the site license was free.

I never cared for it much. To be fair, I never cared for any NTx remote control product. Sooner or later they all crashed servers.

Time went by and RDP took over. I haven't looked at another remote control product in the last five years, primarily due to the fact I work in a "Windows shop".

But VNC development marched on, unrelenting. Now it's up to version 4.1-ish. And now it's not entirely free anymore.

But it has certainly matured.

Although I'd never use anything but RDP on a Windows box these days (and I have seen a few extremely rare BSODs), the options for remote desktop control of a Linux box are more limited.

There's Cygwin X, but it's insecure, it doesn't do NAT (Network Address Translation), and they still have a problem integrating with the Windows clipboard (it worked for about two weeks several revisions ago but not since).

Then there's... well... not much else.

I tried VNC4 on a whim, since it was (is) available in Debian 4.0r0 and most if not all major Linux distros. I was prepared to be disappointed but in the end I was amazed at how well it performs, clipboard and all!

Now I have it on about seven Linux systems. It performs almost as well as RDP, even over an encrypted SSH (Secure Shell) tunnel over the 'Net. Absolutely astounding performance, compared to its earlier days. And the CPU footprint is barely five percent.

When used with VMWare Server (or VMWare Player for that matter), it's a much faster "desktop experience" than the native VMWare client.

And it absolutely leaves Cygwin-X in the dust.

There are a few drawbacks, mostly if you want a multi-user environment, in which case you have to decide how many users you want and which port to run them on (and then educate the end-users, a daunting task).

And of course there's that pesky site license issue.

Your boss'll get over it.

Trust me on that one.